My notes for
@pashov interview on
@SecuritySeries (
@PabloSabbatella):
- Path:
math competitions
-> PC
-> informatics classes
-> university
-> IT company (full-stack)
-> colleague quit to join blockchain
-> got interested
-> self-taught
-> started DeFi development
-> heard about high pay for audits
->
@cmichelio famous article (
cmichel.io/code4rena-first-1…)
-> learned more about
@code4rena
->
@andyfeili videos (
piped.video/@andyli/videos),
@thesecureum Discord
-> Back then huge money for not many hours, multiple times more than developers ~"six figure sum in under a month of work just didn’t make sense, I immediately understood there was something I didn’t know and needed to learn"
-> started contests
- Advice for new auditors
- No need to start as a dev, but most successful SRs were devs
- Even no need to be very technical, there are many examples of non-devs being successful SRs
- Not very likely
- Requires a lot of motivation
- "Mastering Ethereum" is still worth reading, though hard. If you quit it midway, crypto may not be for you. It contains all basics. Can be read in 1-2 weeks
- Try
@cyfrinupdraft, it is very new (it was ~2 months ago). Then their security courses
- After that, start with contests
- Is it important to be self-taught?
- Many people got into SR from
@thesecureum
-
@pashov took Codecademy courses
- Do research, practice, and make money. That’s most important
- Auditing process
- Not that important to listen to others about auditing style (top to bottom, line by line, docs first, etc), find your own style
- He hasn’t done audits in >6 months because he is an audit company founder now
- Choose a contract to start with
- Go line-by-line, character-by-character
- If you don’t understand a line
- Step back
- Go deeper (docs, ask devs)
- Move to another contract for a while
- He personally doesn’t start with docs, but many successful SRs do
- Mostly just read code, think about attacks, nothing special
- Income for SRs
- Private
- On
@PashovAuditGrp and others, usually base pay, stable
-
@SpearbitDAO will pay $20k a week
- In private audits, even if you find nothing for a particular audit, you get paid
- Demand matters a lot, but recent months were the best ever in crypto
- Contests
- Good enough to live in almost any city, but you won’t become rich
- Even with the best bugs, you can get nothing due to escalations or minor rule details
- Better in bull markets: bigger pots, more rewards, more work
- Changes in the field in recent years
- Several contest platforms, different models
- SRs get paid better than ever
- Fewer hacks, fewer bugs in production
- Crazy progress overall
- Tooling
- Not much has changed overall
- Static analysis about the same
- Only fuzzing is doing great
- Some teams start using it
- Maybe not enough to build a business on it alone, but a side product for auditing firms
-
@PashovAuditGrp doesn’t do it
- No big demand
- Better tooling overall
- People
- Natural selection
- Many new people join, but not enough. Slightly more are needed
- Courses help
- Many rising stars
- On-chain audits
- (My note: I haven't heard much about it)
- Not worth the trouble
- Just commit/message hash on-chain is enough
- No demand, not a real problem
- Strategies
- Focus on one field, like ZK
- + Become the “ZK guy,” get more solo gigs, more invitations for consultations
- - Risky if ZK stops being popular
-
@pashov’s strategy
- Focus on everything the first year
- Then specialize in something like lending
- Big TVL
- Big bug bounties
- Tips for protocol companies
- The more time and money spent, the more secure you are
- Hire good devs
- Fewer bugs, fewer audits needed
- Some protocols have 10 critical bugs in 1000 lines found in 1 week, that’s too much and needs multiple rounds to fix
- Multiple audits before deployment
- Every upgrade should be audited
- Tips for audit companies
- It’s best to have a new team for the second round. They will be unbiased (at least in cases where multiple critical bugs were found in the first round)
- Auditing a big project is a big responsibility and a big reputation risk if hacked
- Even big names hire new devs, and you can often find many issues
- Usually big names have great code quality: more money => better devs, better auditors
- Why he founded a company
- After a year of solo audits (50 done), doing everything (marketing, communication, audits), working every day often 12 hours
- Wanted more impact, audit more projects, make more money, have more influence
- Record before opening company: 6-7 audits/month, now 15-16
- Overall quality is better because he works with great SRs
- Some with 10+ years of pentesting and web2 security experience
- Tries to find hidden gems and work with them
- "Use it or lose it," you can’t stay as good of an auditor when running a company
- Coming to web3 from other fields
- If you’re a dev, it’s easy to read Solidity
- Need to learn EVM
- Web2 SRs have a great mindset for finding vulnerabilities
- Best is web2 SR: coding skills plus attacker’s mindset. We see more success from them
- In the end, it’s the individual that matters. Whether web2 SR or dev doesn’t matter too much
- Most important skills
- For
@PashovAuditGrp
- Be a great SR, high quality
- Be unbreakable
- Keep pushing when it’s hard
- Have a lot of experience
- Starting a company
- Much harder without a personal brand (having 20k followers on X helps)
- Marketing is important, hard to find someone to do it for you. Or it will be too expensive, like half of the company
- 10x harder without marketing skills
- Brute forcing, just pushing forward, can make good money but not get rich
- Hardest thing for
@pashov
- Transitioning from auditing to non-technical role
- Had a technical mindset
- Read 1-2 technical articles a day
- Not as good now
- Intentionally makes it look easy, but it’s hard
- Believing in yourself, some beliefs to overcome:
- You can’t make it, it’s too hard
- Hiring is too hard
- Don’t deserve to increase prices
- Clients aren’t happy with the service
- Auditors aren’t doing a good job
- Can’t find good auditors to work with
- Mistakes
-
@PashovAuditGrp
- ~“We’ve done almost everything perfectly”
- Started a bit slower than desired
- Lessons
- If you create good quality content, your business will improve and you’ll get more clients
- Angel investing
- ~"Like a casino but the odds aren’t that much against you"
- Trains your brain to fight cognitive biases, become more rational
- Can make you smarter
- Meet many people, including important ones for business and audits
- Basically a synergy: invest + find clients. A win-win
- Example: Solana 1000x from seed round, a life-changing generational wealth opportunity. Investing $100k could make you rich even in the most expensive part of the world
- Invested in 11 projects, $10-30k each. A minority investor, usually <1%
- Mostly invests in companies his firm audited, when he liked the team and product
- After investing, usually just reads monthly emails from the project and checks their X. Helps when he can, like hiring
- Accepting project tokens as payment
-
@PashovAuditGrp doesn’t do it
- Most don’t have a project token yet
- If they don’t have a token, it requires more documentation (like a pre-ICO agreement)
- The project can dump the token
- Rarely a good fit
- Almost all pay in USDC/USDT
- Resources
- Read crypto Twitter/X. He spends hours a day there
- Check who he follows and follow them for a good feed
- Rarely reads newsletters
- Conferences
- The biggest ones are the best
- Attends 1 or 2 a year
- Can waste a lot of time and energy, so he focuses on work more
- Great to meet people
- Before going, find who will do your job while you're out
- A lot of value, but time-consuming
- Anyone can reach him on X, DMs are open, happy to work with a good fit
-
piped.video/watch?v=5THmZQXj…